4 ms·
> From an end-user POV, what will using an Arc app entail? If Arc is installed, you're good to go. Everything just works. If Arc isn't installed 1) arc.js t
by grun 13y ago
> From an end-user POV, what will using an Arc app entail?
If Arc is installed, you're good to go. Everything just works. If Arc isn't
installed
1) arc.js transparently falls back to the cloud and runs the Arc app on a
server. The user doesn't know the difference.
and/or
2) Upsell the user to install Arc.
I haven't built the transparent cloud fallback yet.
> What is to prevent other websites from being malicious and connecting to your
> locally-installed Peggo VM and trashing it or otherwise exploiting it?
The web server running in the Arc app can check the Referer header to verify the
request came from a permissible domain.
- JangoSteve 13y agoCan the Referrer header not be spoofed?
- sehrope 13y agoSpoofing it in a client's browser is not possible but it's trivial to spoof referrer headers (or anything else) from a stand alone program. Beyond checking for referrer headers the server should give the client a signed token (returned back by the client to the server) to verify the request is valid. Otherwise if the client is arbitrarily sending requests to the server to "install X, run Y, ..." it'd be very easy to hijack the server for other processing. As usual this goes back to one of the standard rules of server security: Don't trust anything that comes from the client.
- iooi 13y agoSpoofing with a client is easily done. In Firefox you can use TamperData.